cbcvebase.
CVE-2024-40938
published 2024-07-12

CVE-2024-40938: In the Linux kernel, the following vulnerability has been resolved: landlock: Fix d_parent walk The WARN_ON_ONCE() in collect_domain_accesses() can be…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.5th percentile
In the Linux kernel, the following vulnerability has been resolved: landlock: Fix d_parent walk The WARN_ON_ONCE() in collect_domain_accesses() can be triggered when trying to link a root mount point. This cannot work in practice because this directory is mounted, but the VFS check is done after the call to security_path_link(). Do not use source directory's d_parent when the source directory is the mount point. [mic: Fix commit message]

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= b91c3e4ea756b12b7d992529226edce1cfd854d7 < b6e5e696435832b33e40775f060ef5c95f4fda1fb6e5e696435832b33e40775f060ef5c95f4fda1f
linuxlinux>= b91c3e4ea756b12b7d992529226edce1cfd854d7 < cc30d05b34f9a087a6928d09b131f7b491e9ab11cc30d05b34f9a087a6928d09b131f7b491e9ab11
linuxlinux>= b91c3e4ea756b12b7d992529226edce1cfd854d7 < c7618c7b0b8c45bcef34410cc1d1e953eb17f8f6c7618c7b0b8c45bcef34410cc1d1e953eb17f8f6
linuxlinux>= b91c3e4ea756b12b7d992529226edce1cfd854d7 < 88da52ccd66e65f2e63a6c35c9dff55d448ef4dc88da52ccd66e65f2e63a6c35c9dff55d448ef4dc
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.19 < 6.1.956.1.95
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.